CVE-2026-26718

CRITICAL

xxl-job-admin 3.0.0 - Cross-Site Request Forgery via Glue IDE Shell Script Modification Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-26718. PoCs published by Ibrahim-Sartawi.

AI-analyzed exploit summary This repository demonstrates a CSRF vulnerability in xxl-job-admin < 3.4.0, allowing unauthorized modifications to Glue IDE shell scripts via a crafted HTML form that bypasses CSRF token validation. The PoC includes a functional exploit that executes arbitrary shell commands when submitted by an authenticated administrator.

Description

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping

Exploits (1)

github WORKING POC
by Ibrahim-Sartawi · poc
https://github.com/Ibrahim-Sartawi/CVE-2026-26718

This repository demonstrates a CSRF vulnerability in xxl-job-admin < 3.4.0, allowing unauthorized modifications to Glue IDE shell scripts via a crafted HTML form that bypasses CSRF token validation. The PoC includes a functional exploit that executes arbitrary shell commands when submitted by an authenticated administrator.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: xxl-job-admin < 3.4.0
Auth required
Prerequisites: Attacker must trick an authenticated administrator into visiting the malicious HTML page · Target must be running a vulnerable version of xxl-job-admin
mistral-large-3 · analyzed Jul 16, 2026 Full analysis →

Scores

CVSS v3 9.1
EPSS 0.0022
EPSS Percentile 13.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-352
Status published
Published Jul 15, 2026
Tracked Since Jul 16, 2026